Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected, FRST.Log


  • This topic is locked This topic is locked
3 replies to this topic

#1 ed-e-dee

ed-e-dee

  • Members
  • 276 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Australia
  • Local time:04:31 AM

Posted 28 February 2018 - 01:05 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.02.2018
Ran by admin (administrator) on COMPUTER (28-02-2018 16:56:12)
Running from C:\Users\admin\Downloads
Loaded Profiles: admin (Available Profiles: admin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
() C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Corel Corporation) C:\Program Files\WinZip\WinZip Smart Monitor\WinZipCompressionSmartMonitor.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\admin\Downloads\FRST64 (2).exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16781824 2017-01-11] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-01-22] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [243496 2018-02-24] (AVAST Software)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2047744 2017-12-11] (WinZip)
HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [123848 2017-12-11] (WinZip Computing, S.L.)
HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436416 2017-12-11] (WinZip Computing, S.L.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10290608 2018-02-08] (Piriform Ltd)
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2018-01-10] (Apple Inc.)
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1422248 2018-02-08] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1422248 2018-02-08] (Garmin Ltd. or its subsidiaries)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ACD34803-69FB-4916-85D8-E273049B937D}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{BB87E0A3-252A-4D07-BE03-06DBCBE54D28}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com.au/?gws_rd=ssl
SearchScopes: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003 -> DefaultScope {0C7B1F9C-21F0-4959-A111-2621F4D4164B} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003 -> {0C7B1F9C-21F0-4959-A111-2621F4D4164B} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-02-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-04-27] (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-02-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-04-27] (Google Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-04-27] (Google Inc.)
Toolbar: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-04-27] (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
 
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d6yz4vy0.default-1444897521109 [2018-02-24]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-12-03] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll [2018-02-26] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll [2018-02-26] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-10] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-10] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1382244373-2055223747-3369237834-1003: @tools.google.com/Google Update;version=3 -> C:\Users\admin\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1382244373-2055223747-3369237834-1003: @tools.google.com/Google Update;version=9 -> C:\Users\admin\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-28] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2018-02-28]
CHR Extension: (Slides) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-16]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-16]
CHR Extension: (Sheets) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Virtual Piano Black) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo [2016-06-16]
CHR Extension: (Google Docs Offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-16]
CHR Extension: (Discrete Search) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjhiajafgpbijomjilfpkfemmhdoponb [2016-12-13]
CHR Extension: (Grammarly for Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-02-16]
CHR Extension: (True Key™ by Intel Security) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbeldjopgciegccabfohnefghfpinncn [2017-10-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-16]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-28]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-09] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-01-05] (Apple Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7564512 2018-02-24] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [300600 2018-02-24] (AVAST Software)
S4 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1162768 2018-02-08] (Garmin Ltd. or its subsidiaries)
S4 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S4 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation)
S4 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S4 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WinZip Compression Smart Monitor Service; C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe [495872 2017-09-01] ()
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AcpiCtlDrv; C:\Windows\System32\DRIVERS\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [192944 2018-02-24] (AVAST Software)
S3 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2018-02-24] (AVAST Software)
S3 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2018-02-24] (AVAST Software)
S3 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2018-02-24] (AVAST Software)
S3 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2018-02-24] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [190440 2018-02-24] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-02-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146648 2018-02-24] (AVAST Software)
S3 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-02-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-02-24] (AVAST Software)
S3 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-02-24] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [459952 2018-02-24] (AVAST Software)
S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [205464 2018-02-24] (AVAST Software)
S3 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [379448 2018-02-24] (AVAST Software)
S1 avipbb; C:\Windows\SysWOW64\DRIVERS\avipbb.sys [145984 2016-08-19] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\SysWOW64\DRIVERS\avkmgr.sys [28600 2016-08-19] (Avira Operations GmbH & Co. KG)
R1 epp; C:\EEK\bin64\epp.sys [124080 2016-02-11] (Emsisoft Ltd)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [31712 2016-08-30] (Intel Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2017-12-14] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [199760 2016-11-29] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKslf43bf7a5; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FD691C8A-B3B0-46BF-8CAC-74156F34E13E}\MpKslf43bf7a5.sys [58120 2018-02-28] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [23552 2013-11-26] (Windows ® Win 7 DDK provider)
R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [86016 2013-11-26] (Nuvoton Technology Corp.)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [221696 2015-08-21] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [294912 2015-08-21] (VIA Technologies, Inc.)
R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation)
U3 aswbdisk; no ImagePath
S3 b06bdrv; \SystemRoot\system32\drivers\bxvbda.sys [X]
S3 farflt; \??\C:\Windows\system32\drivers\farflt.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-28 16:53 - 2018-02-28 16:53 - 002403328 ____C (Farbar) C:\Users\admin\Downloads\FRST64 (2).exe
2018-02-27 16:30 - 2018-02-27 16:31 - 000049604 ____C C:\Users\admin\Downloads\Oliver.htm
2018-02-26 17:59 - 2018-02-26 17:59 - 000001070 ____C C:\Users\Public\Desktop\VLC media player.lnk
2018-02-26 17:58 - 2018-02-26 17:58 - 000003404 ____C C:\Windows\System32\Tasks\WinZip Update Notifier
2018-02-26 17:58 - 2018-02-26 17:58 - 000001881 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk
2018-02-26 17:58 - 2018-02-26 17:58 - 000001781 ____C C:\Users\Public\Desktop\WinZip.lnk
2018-02-26 17:58 - 2018-02-26 17:58 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 22.0
2018-02-26 17:57 - 2018-02-26 17:57 - 000000000 ___DC C:\Users\admin\AppData\Local\AVAST Software
2018-02-25 22:23 - 2018-02-25 22:23 - 000002132 ____C C:\Users\admin\Desktop\Rkill.txt
2018-02-24 21:32 - 2018-02-24 21:32 - 000000000 ___DC C:\Users\admin\AppData\Roaming\AVAST Software
2018-02-24 21:27 - 2018-02-27 16:01 - 000004168 ____C C:\Windows\System32\Tasks\Avast Emergency Update
2018-02-24 21:27 - 2018-02-24 21:27 - 000001882 ____C C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2018-02-24 21:27 - 2018-02-24 21:27 - 000000000 ___DC C:\Windows\System32\Tasks\Avast Software
2018-02-24 21:27 - 2018-02-24 21:27 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2018-02-24 21:27 - 2018-02-24 21:26 - 001026696 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000459952 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000380768 ____C (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-02-24 21:27 - 2018-02-24 21:26 - 000379448 ____C (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000343768 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000321512 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000205464 ____C (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000199448 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000192944 ____C (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000190440 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000146648 ____C (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000110328 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000084368 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000057696 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000046968 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-02-24 21:24 - 2018-02-24 21:24 - 000002860 ____C C:\Users\admin\Documents\cc_20180224_212432.reg
2018-02-24 21:24 - 2018-02-24 21:24 - 000000000 ___DC C:\Program Files\AVAST Software
2018-02-24 21:22 - 2018-02-24 21:23 - 011217568 ____C (Piriform Ltd) C:\Users\admin\Downloads\ccsetup540.exe
2018-02-22 17:20 - 2018-02-22 17:20 - 000197219 ____C C:\Users\admin\Downloads\Invoice_258_209238.pdf
2018-02-18 16:47 - 2018-02-18 16:55 - 000049846 ____C C:\Users\admin\Downloads\you are how old.htm
2018-02-16 22:41 - 2018-02-16 22:41 - 006968952 ____C (ESET spol. s r.o.) C:\Users\admin\Downloads\esetonlinescanner_enu.exe
2018-02-16 22:41 - 2018-02-16 22:41 - 000000000 ___DC C:\Users\admin\AppData\Local\ESET
2018-02-16 22:37 - 2018-02-16 22:37 - 008222496 ____C (Malwarebytes) C:\Users\admin\Downloads\AdwCleaner (3).exe
2018-02-16 22:35 - 2018-02-16 22:35 - 008222496 ____C (Malwarebytes) C:\Users\admin\Downloads\AdwCleaner (2).exe
2018-02-16 22:24 - 2018-02-16 22:24 - 008222496 ____C (Malwarebytes) C:\Users\admin\Downloads\AdwCleaner (1).exe
2018-02-16 22:20 - 2018-02-16 22:20 - 000892416 ____C (Farbar) C:\Users\admin\Downloads\MiniToolBox (7).exe
2018-02-16 22:17 - 2018-02-16 22:17 - 000892416 ____C (Farbar) C:\Users\admin\Downloads\MiniToolBox (6).exe
2018-02-16 22:04 - 2018-02-16 22:04 - 000001303 ____C C:\Users\admin\Desktop\Online Auto parts.htm
2018-02-14 12:02 - 2018-02-14 12:02 - 000000000 __SDC C:\ComboFix
2018-02-14 11:43 - 2018-02-14 11:43 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2018-02-14 11:39 - 2018-02-14 21:40 - 025740288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 020274176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 005782016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 004834816 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 004498944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 004014312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 003224064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-02-14 11:39 - 2018-02-14 21:40 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-02-14 11:39 - 2018-02-14 21:40 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-02-14 11:39 - 2018-02-14 21:40 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-02-14 11:39 - 2018-02-14 21:40 - 001894120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001484288 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001176576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-02-14 11:39 - 2018-02-14 21:40 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-02-14 11:39 - 2018-02-14 21:40 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-02-14 11:39 - 2018-02-14 21:40 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000404992 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000395928 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000377064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000371432 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000347296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-02-14 11:39 - 2018-02-14 21:40 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-02-14 11:39 - 2018-02-14 21:40 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000218112 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-02-14 11:39 - 2018-02-14 21:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-02-14 11:39 - 2018-02-14 21:40 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-02-14 11:39 - 2018-01-13 03:16 - 000076288 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-02-14 11:39 - 2018-01-13 03:16 - 000030208 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-02-14 11:39 - 2018-01-13 03:15 - 000032896 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-02-14 11:38 - 2018-02-14 21:39 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-02-14 11:38 - 2018-02-14 21:39 - 001569280 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000654336 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000604672 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000236544 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000136424 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-02-13 10:51 - 2018-02-13 10:51 - 000584808 ____C C:\Users\admin\Downloads\speccy.piriform.com.html
2018-02-13 10:51 - 2018-02-13 10:51 - 000000000 ___DC C:\Users\admin\Downloads\speccy.piriform.com_files
2018-02-13 10:38 - 2018-02-13 10:38 - 000020236 ____C C:\Users\admin\Documents\COMPUTER.speccy
2018-02-13 10:33 - 2018-02-13 11:48 - 000000000 ___DC C:\Program Files\Speccy
2018-02-13 10:33 - 2018-02-13 10:33 - 006299336 ____C (Piriform Ltd) C:\Users\admin\Downloads\spsetup131.exe
2018-02-13 10:33 - 2018-02-13 10:33 - 000000756 ____C C:\Users\Public\Desktop\Speccy.lnk
2018-02-13 10:33 - 2018-02-13 10:33 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2018-02-13 10:27 - 2018-02-13 10:27 - 000892416 ____C (Farbar) C:\Users\admin\Downloads\MiniToolBox (5).exe
2018-02-12 16:28 - 2018-02-12 16:28 - 000032986 ____C C:\Users\admin\Downloads\Statement_Feb 2018.pdf
2018-02-11 17:01 - 2018-02-11 17:01 - 001023682 ____C C:\Users\admin\Downloads\Cooling.pdf
2018-02-09 23:09 - 2018-02-09 23:09 - 000000239 ____C C:\Users\admin\Desktop\VZ Holden Commodore (2004 - 2006)  Just Commodores.url
2018-02-09 16:40 - 2018-02-09 16:40 - 000002104 ____C C:\Users\admin\Documents\cc_20180209_164024.reg
2018-02-09 16:37 - 2018-02-09 16:37 - 011205832 ____C (Piriform Ltd) C:\Users\admin\Downloads\ccsetup539 (2).exe
2018-02-09 16:35 - 2018-02-09 16:35 - 011205832 ____C (Piriform Ltd) C:\Users\admin\Downloads\ccsetup539 (1).exe
2018-02-08 17:44 - 2018-02-08 17:44 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2018-02-08 17:43 - 2018-02-08 17:43 - 000001707 ____C C:\Users\Public\Desktop\iTunes.lnk
2018-02-08 17:43 - 2018-02-08 17:43 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-02-08 17:43 - 2018-02-08 17:43 - 000000000 ___DC C:\Program Files\iTunes
2018-02-08 17:43 - 2018-02-08 17:43 - 000000000 ___DC C:\Program Files\iPod
2018-02-05 20:28 - 2018-02-05 20:28 - 000000000 ___DC C:\Users\admin\Desktop\Jaguar
2018-02-05 20:27 - 2018-02-05 20:27 - 000000000 ___DC C:\Users\admin\Desktop\2016-03-16 mothers chair
2018-02-05 20:25 - 2018-02-05 20:25 - 000000000 ___DC C:\Users\admin\Desktop\Cannon 120
2018-02-05 20:21 - 2018-02-05 20:21 - 000000000 ___DC C:\Users\admin\Desktop\Pentex film camera
2018-02-05 20:18 - 2018-02-05 20:18 - 000000000 ___DC C:\Users\admin\Desktop\2014-10-07 Sony stereo
2018-02-05 20:16 - 2018-02-05 20:16 - 000000000 ___DC C:\Users\admin\Desktop\Wine Chiller
2018-02-05 20:14 - 2018-02-05 20:14 - 000000000 ___DC C:\Users\admin\Desktop\Piano stool
2018-02-05 20:10 - 2018-02-05 20:10 - 000000000 ___DC C:\Users\admin\Desktop\Pressure cleaner
2018-02-05 20:08 - 2018-02-05 20:08 - 000000000 ___DC C:\Users\admin\Desktop\golf bag
2018-02-05 20:07 - 2018-02-07 12:51 - 000000000 ___DC C:\Users\admin\Desktop\2018-02-05 Golf bag
2018-02-05 19:58 - 2018-02-09 16:38 - 000000000 ___DC C:\Windows\Minidump
2018-02-04 12:43 - 2018-02-04 12:43 - 000550424 ____C () C:\Users\admin\Downloads\iExplorerSetup.exe
2018-02-03 15:28 - 2018-02-03 15:28 - 000001791 ____C C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-01-30 09:26 - 2018-01-30 09:26 - 000431151 ____C C:\Users\admin\Downloads\agl_bill (2).pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-28 16:56 - 2015-10-15 13:23 - 000020110 ____C C:\Users\admin\Downloads\FRST.txt
2018-02-28 16:56 - 2015-10-13 15:59 - 000000000 ___DC C:\FRST
2018-02-28 15:08 - 2009-07-14 14:20 - 000000000 ___DC C:\Windows\tracing
2018-02-28 11:34 - 2015-05-13 19:34 - 000004476 ____C C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-28 11:29 - 2009-07-14 15:45 - 000026000 ____C C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-02-28 11:29 - 2009-07-14 15:45 - 000026000 ____C C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-02-28 11:25 - 2009-07-14 16:13 - 000783606 ____C C:\Windows\system32\PerfStringBackup.INI
2018-02-28 11:25 - 2009-07-14 14:20 - 000000000 ___DC C:\Windows\inf
2018-02-28 11:21 - 2015-06-13 15:04 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2018-02-28 11:21 - 2009-07-14 16:08 - 000000006 ___HC C:\Windows\Tasks\SA.DAT
2018-02-27 16:37 - 2016-06-16 19:36 - 000002224 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-27 16:37 - 2016-06-16 19:36 - 000002183 ____C C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-27 16:23 - 2009-07-14 14:20 - 000000000 ___DC C:\Windows\system32\NDF
2018-02-27 16:15 - 2017-11-10 11:41 - 000004128 ____C C:\Windows\System32\Tasks\CCleaner Update
2018-02-27 11:12 - 2014-07-24 17:30 - 000000000 ___DC C:\Windows\system32\Macromed
2018-02-26 17:59 - 2016-04-17 23:08 - 000000000 ___DC C:\ProgramData\WinZip
2018-02-26 17:58 - 2016-04-17 23:08 - 000000000 ___DC C:\Users\admin\AppData\Local\WinZip
2018-02-26 17:58 - 2016-04-17 23:08 - 000000000 ___DC C:\Program Files\WinZip
2018-02-26 17:57 - 2015-10-08 17:07 - 000004312 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-02-26 17:57 - 2014-07-24 17:30 - 000803328 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-02-26 17:57 - 2014-07-24 17:30 - 000144896 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-26 17:57 - 2014-07-24 17:30 - 000000000 ___DC C:\Windows\SysWOW64\Macromed
2018-02-25 21:54 - 2016-05-13 21:12 - 000002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-02-24 21:23 - 2017-04-09 13:53 - 000000000 ___DC C:\ProgramData\AVAST Software
2018-02-24 21:23 - 2017-02-14 22:04 - 000000782 ____C C:\Users\Public\Desktop\CCleaner.lnk
2018-02-16 22:37 - 2016-02-06 17:00 - 000000000 ___DC C:\AdwCleaner
2018-02-16 22:22 - 2015-09-13 21:18 - 000035142 ____C C:\Users\admin\Downloads\MTB.txt
2018-02-15 15:38 - 2014-12-12 08:38 - 000000000 ___DC C:\Windows\system32\appraiser
2018-02-15 15:38 - 2009-07-14 15:45 - 000294496 ____C C:\Windows\system32\FNTCACHE.DAT
2018-02-14 21:42 - 2014-04-29 13:08 - 000000000 ___DC C:\Windows\system32\MRT
2018-02-14 21:41 - 2017-10-11 21:37 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-14 21:41 - 2014-09-18 13:59 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-02-14 12:02 - 2015-05-13 19:14 - 000000000 ___DC C:\Qoobox
2018-02-14 11:43 - 2016-01-30 14:48 - 000003554 ____C C:\Windows\System32\Tasks\GarminUpdaterTask
2018-02-14 11:43 - 2014-10-10 16:17 - 000000000 ___DC C:\Program Files (x86)\Garmin
2018-02-14 11:43 - 2014-09-22 11:05 - 000000000 ___DC C:\ProgramData\Package Cache
2018-02-12 18:02 - 2017-11-10 11:29 - 000000000 ___DC C:\Users\admin\Desktop\OpenOffice 4.1.4 (en-US) Installation Files
2018-02-12 17:59 - 2015-05-13 19:10 - 000000000 ___DC C:\Users\admin\AppData\Local\CrashDumps
2018-02-09 23:05 - 2015-11-01 19:47 - 000000000 ___DC C:\Users\admin\AppData\Local\Deployment
2018-02-04 21:31 - 2014-09-17 14:14 - 000759576 ____C C:\Windows\SysWOW64\PerfStringBackup.INI
2018-02-04 12:43 - 2015-11-01 19:47 - 000000000 ___DC C:\Users\admin\AppData\Local\Apps\2.0
2018-02-03 15:38 - 2017-12-03 16:24 - 000000000 ___DC C:\Users\admin\Desktop\2017-12-03 exersize machines
2018-02-03 15:26 - 2016-02-07 13:16 - 000000000 ___DC C:\Users\admin\Desktop\Items I Don't Use
2018-01-30 18:03 - 2014-07-26 09:32 - 000001583 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2018-01-30 11:29 - 2014-07-26 04:19 - 000000000 ___DC C:\Users\admin\AppData\Local\ElevatedDiagnostics
 
==================== Files in the root of some directories =======
 
2014-12-24 10:46 - 2015-07-04 22:55 - 000000115 ____C () C:\Users\admin\AppData\Roaming\LogFile.txt
2014-07-24 20:02 - 2014-08-02 20:10 - 000018526 ____C () C:\Users\admin\AppData\Roaming\UserTile.png
2014-09-26 21:22 - 2016-02-01 18:43 - 000004608 ____C () C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2016-11-29 19:47
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.02.2018
Ran by admin (28-02-2018 16:56:44)
Running from C:\Users\admin\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-09-17 03:09:53)
Boot Mode: NormalScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.02.2018
Ran by admin (administrator) on COMPUTER (28-02-2018 16:56:12)
Running from C:\Users\admin\Downloads
Loaded Profiles: admin (Available Profiles: admin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
() C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Corel Corporation) C:\Program Files\WinZip\WinZip Smart Monitor\WinZipCompressionSmartMonitor.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\admin\Downloads\FRST64 (2).exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16781824 2017-01-11] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-01-22] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [243496 2018-02-24] (AVAST Software)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2047744 2017-12-11] (WinZip)
HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [123848 2017-12-11] (WinZip Computing, S.L.)
HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436416 2017-12-11] (WinZip Computing, S.L.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10290608 2018-02-08] (Piriform Ltd)
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2018-01-10] (Apple Inc.)
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1422248 2018-02-08] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1422248 2018-02-08] (Garmin Ltd. or its subsidiaries)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ACD34803-69FB-4916-85D8-E273049B937D}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{BB87E0A3-252A-4D07-BE03-06DBCBE54D28}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com.au/?gws_rd=ssl
SearchScopes: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003 -> DefaultScope {0C7B1F9C-21F0-4959-A111-2621F4D4164B} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003 -> {0C7B1F9C-21F0-4959-A111-2621F4D4164B} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-02-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-04-27] (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-02-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-04-27] (Google Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-04-27] (Google Inc.)
Toolbar: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-04-27] (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
 
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\d6yz4vy0.default-1444897521109 [2018-02-24]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-12-03] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll [2018-02-26] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll [2018-02-26] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-10] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-10] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1382244373-2055223747-3369237834-1003: @tools.google.com/Google Update;version=3 -> C:\Users\admin\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1382244373-2055223747-3369237834-1003: @tools.google.com/Google Update;version=9 -> C:\Users\admin\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-28] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2018-02-28]
CHR Extension: (Slides) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-16]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-16]
CHR Extension: (Sheets) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Virtual Piano Black) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo [2016-06-16]
CHR Extension: (Google Docs Offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-16]
CHR Extension: (Discrete Search) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjhiajafgpbijomjilfpkfemmhdoponb [2016-12-13]
CHR Extension: (Grammarly for Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-02-16]
CHR Extension: (True Key™ by Intel Security) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbeldjopgciegccabfohnefghfpinncn [2017-10-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-16]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-28]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-09] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-01-05] (Apple Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7564512 2018-02-24] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [300600 2018-02-24] (AVAST Software)
S4 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1162768 2018-02-08] (Garmin Ltd. or its subsidiaries)
S4 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S4 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation)
S4 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S4 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WinZip Compression Smart Monitor Service; C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe [495872 2017-09-01] ()
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AcpiCtlDrv; C:\Windows\System32\DRIVERS\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [192944 2018-02-24] (AVAST Software)
S3 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2018-02-24] (AVAST Software)
S3 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2018-02-24] (AVAST Software)
S3 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2018-02-24] (AVAST Software)
S3 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2018-02-24] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [190440 2018-02-24] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-02-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146648 2018-02-24] (AVAST Software)
S3 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-02-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-02-24] (AVAST Software)
S3 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-02-24] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [459952 2018-02-24] (AVAST Software)
S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [205464 2018-02-24] (AVAST Software)
S3 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [379448 2018-02-24] (AVAST Software)
S1 avipbb; C:\Windows\SysWOW64\DRIVERS\avipbb.sys [145984 2016-08-19] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\SysWOW64\DRIVERS\avkmgr.sys [28600 2016-08-19] (Avira Operations GmbH & Co. KG)
R1 epp; C:\EEK\bin64\epp.sys [124080 2016-02-11] (Emsisoft Ltd)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [31712 2016-08-30] (Intel Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2017-12-14] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [199760 2016-11-29] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKslf43bf7a5; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FD691C8A-B3B0-46BF-8CAC-74156F34E13E}\MpKslf43bf7a5.sys [58120 2018-02-28] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [23552 2013-11-26] (Windows ® Win 7 DDK provider)
R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [86016 2013-11-26] (Nuvoton Technology Corp.)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [221696 2015-08-21] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [294912 2015-08-21] (VIA Technologies, Inc.)
R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation)
U3 aswbdisk; no ImagePath
S3 b06bdrv; \SystemRoot\system32\drivers\bxvbda.sys [X]
S3 farflt; \??\C:\Windows\system32\drivers\farflt.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-28 16:53 - 2018-02-28 16:53 - 002403328 ____C (Farbar) C:\Users\admin\Downloads\FRST64 (2).exe
2018-02-27 16:30 - 2018-02-27 16:31 - 000049604 ____C C:\Users\admin\Downloads\Oliver.htm
2018-02-26 17:59 - 2018-02-26 17:59 - 000001070 ____C C:\Users\Public\Desktop\VLC media player.lnk
2018-02-26 17:58 - 2018-02-26 17:58 - 000003404 ____C C:\Windows\System32\Tasks\WinZip Update Notifier
2018-02-26 17:58 - 2018-02-26 17:58 - 000001881 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk
2018-02-26 17:58 - 2018-02-26 17:58 - 000001781 ____C C:\Users\Public\Desktop\WinZip.lnk
2018-02-26 17:58 - 2018-02-26 17:58 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 22.0
2018-02-26 17:57 - 2018-02-26 17:57 - 000000000 ___DC C:\Users\admin\AppData\Local\AVAST Software
2018-02-25 22:23 - 2018-02-25 22:23 - 000002132 ____C C:\Users\admin\Desktop\Rkill.txt
2018-02-24 21:32 - 2018-02-24 21:32 - 000000000 ___DC C:\Users\admin\AppData\Roaming\AVAST Software
2018-02-24 21:27 - 2018-02-27 16:01 - 000004168 ____C C:\Windows\System32\Tasks\Avast Emergency Update
2018-02-24 21:27 - 2018-02-24 21:27 - 000001882 ____C C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2018-02-24 21:27 - 2018-02-24 21:27 - 000000000 ___DC C:\Windows\System32\Tasks\Avast Software
2018-02-24 21:27 - 2018-02-24 21:27 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2018-02-24 21:27 - 2018-02-24 21:26 - 001026696 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000459952 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000380768 ____C (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-02-24 21:27 - 2018-02-24 21:26 - 000379448 ____C (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000343768 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000321512 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000205464 ____C (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000199448 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000192944 ____C (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000190440 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000146648 ____C (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000110328 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000084368 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000057696 ____C (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2018-02-24 21:27 - 2018-02-24 21:26 - 000046968 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-02-24 21:24 - 2018-02-24 21:24 - 000002860 ____C C:\Users\admin\Documents\cc_20180224_212432.reg
2018-02-24 21:24 - 2018-02-24 21:24 - 000000000 ___DC C:\Program Files\AVAST Software
2018-02-24 21:22 - 2018-02-24 21:23 - 011217568 ____C (Piriform Ltd) C:\Users\admin\Downloads\ccsetup540.exe
2018-02-22 17:20 - 2018-02-22 17:20 - 000197219 ____C C:\Users\admin\Downloads\Invoice_258_209238.pdf
2018-02-18 16:47 - 2018-02-18 16:55 - 000049846 ____C C:\Users\admin\Downloads\you are how old.htm
2018-02-16 22:41 - 2018-02-16 22:41 - 006968952 ____C (ESET spol. s r.o.) C:\Users\admin\Downloads\esetonlinescanner_enu.exe
2018-02-16 22:41 - 2018-02-16 22:41 - 000000000 ___DC C:\Users\admin\AppData\Local\ESET
2018-02-16 22:37 - 2018-02-16 22:37 - 008222496 ____C (Malwarebytes) C:\Users\admin\Downloads\AdwCleaner (3).exe
2018-02-16 22:35 - 2018-02-16 22:35 - 008222496 ____C (Malwarebytes) C:\Users\admin\Downloads\AdwCleaner (2).exe
2018-02-16 22:24 - 2018-02-16 22:24 - 008222496 ____C (Malwarebytes) C:\Users\admin\Downloads\AdwCleaner (1).exe
2018-02-16 22:20 - 2018-02-16 22:20 - 000892416 ____C (Farbar) C:\Users\admin\Downloads\MiniToolBox (7).exe
2018-02-16 22:17 - 2018-02-16 22:17 - 000892416 ____C (Farbar) C:\Users\admin\Downloads\MiniToolBox (6).exe
2018-02-16 22:04 - 2018-02-16 22:04 - 000001303 ____C C:\Users\admin\Desktop\Online Auto parts.htm
2018-02-14 12:02 - 2018-02-14 12:02 - 000000000 __SDC C:\ComboFix
2018-02-14 11:43 - 2018-02-14 11:43 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2018-02-14 11:39 - 2018-02-14 21:40 - 025740288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 020274176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 005782016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 004834816 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 004498944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 004014312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 003224064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-02-14 11:39 - 2018-02-14 21:40 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-02-14 11:39 - 2018-02-14 21:40 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-02-14 11:39 - 2018-02-14 21:40 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-02-14 11:39 - 2018-02-14 21:40 - 001894120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001484288 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001176576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-02-14 11:39 - 2018-02-14 21:40 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-02-14 11:39 - 2018-02-14 21:40 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-02-14 11:39 - 2018-02-14 21:40 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000404992 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000395928 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000377064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000371432 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000347296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-02-14 11:39 - 2018-02-14 21:40 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-02-14 11:39 - 2018-02-14 21:40 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000218112 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-02-14 11:39 - 2018-02-14 21:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-02-14 11:39 - 2018-02-14 21:40 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-02-14 11:39 - 2018-02-14 21:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-02-14 11:39 - 2018-02-14 21:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-02-14 11:39 - 2018-02-14 21:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-02-14 11:39 - 2018-01-13 03:16 - 000076288 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-02-14 11:39 - 2018-01-13 03:16 - 000030208 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-02-14 11:39 - 2018-01-13 03:15 - 000032896 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-02-14 11:38 - 2018-02-14 21:39 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-02-14 11:38 - 2018-02-14 21:39 - 001569280 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000654336 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000604672 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000236544 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-02-14 11:38 - 2018-02-14 21:39 - 000136424 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-02-13 10:51 - 2018-02-13 10:51 - 000584808 ____C C:\Users\admin\Downloads\speccy.piriform.com.html
2018-02-13 10:51 - 2018-02-13 10:51 - 000000000 ___DC C:\Users\admin\Downloads\speccy.piriform.com_files
2018-02-13 10:38 - 2018-02-13 10:38 - 000020236 ____C C:\Users\admin\Documents\COMPUTER.speccy
2018-02-13 10:33 - 2018-02-13 11:48 - 000000000 ___DC C:\Program Files\Speccy
2018-02-13 10:33 - 2018-02-13 10:33 - 006299336 ____C (Piriform Ltd) C:\Users\admin\Downloads\spsetup131.exe
2018-02-13 10:33 - 2018-02-13 10:33 - 000000756 ____C C:\Users\Public\Desktop\Speccy.lnk
2018-02-13 10:33 - 2018-02-13 10:33 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2018-02-13 10:27 - 2018-02-13 10:27 - 000892416 ____C (Farbar) C:\Users\admin\Downloads\MiniToolBox (5).exe
2018-02-12 16:28 - 2018-02-12 16:28 - 000032986 ____C C:\Users\admin\Downloads\Statement_Feb 2018.pdf
2018-02-11 17:01 - 2018-02-11 17:01 - 001023682 ____C C:\Users\admin\Downloads\Cooling.pdf
2018-02-09 23:09 - 2018-02-09 23:09 - 000000239 ____C C:\Users\admin\Desktop\VZ Holden Commodore (2004 - 2006)  Just Commodores.url
2018-02-09 16:40 - 2018-02-09 16:40 - 000002104 ____C C:\Users\admin\Documents\cc_20180209_164024.reg
2018-02-09 16:37 - 2018-02-09 16:37 - 011205832 ____C (Piriform Ltd) C:\Users\admin\Downloads\ccsetup539 (2).exe
2018-02-09 16:35 - 2018-02-09 16:35 - 011205832 ____C (Piriform Ltd) C:\Users\admin\Downloads\ccsetup539 (1).exe
2018-02-08 17:44 - 2018-02-08 17:44 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2018-02-08 17:43 - 2018-02-08 17:43 - 000001707 ____C C:\Users\Public\Desktop\iTunes.lnk
2018-02-08 17:43 - 2018-02-08 17:43 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-02-08 17:43 - 2018-02-08 17:43 - 000000000 ___DC C:\Program Files\iTunes
2018-02-08 17:43 - 2018-02-08 17:43 - 000000000 ___DC C:\Program Files\iPod
2018-02-05 20:28 - 2018-02-05 20:28 - 000000000 ___DC C:\Users\admin\Desktop\Jaguar
2018-02-05 20:27 - 2018-02-05 20:27 - 000000000 ___DC C:\Users\admin\Desktop\2016-03-16 mothers chair
2018-02-05 20:25 - 2018-02-05 20:25 - 000000000 ___DC C:\Users\admin\Desktop\Cannon 120
2018-02-05 20:21 - 2018-02-05 20:21 - 000000000 ___DC C:\Users\admin\Desktop\Pentex film camera
2018-02-05 20:18 - 2018-02-05 20:18 - 000000000 ___DC C:\Users\admin\Desktop\2014-10-07 Sony stereo
2018-02-05 20:16 - 2018-02-05 20:16 - 000000000 ___DC C:\Users\admin\Desktop\Wine Chiller
2018-02-05 20:14 - 2018-02-05 20:14 - 000000000 ___DC C:\Users\admin\Desktop\Piano stool
2018-02-05 20:10 - 2018-02-05 20:10 - 000000000 ___DC C:\Users\admin\Desktop\Pressure cleaner
2018-02-05 20:08 - 2018-02-05 20:08 - 000000000 ___DC C:\Users\admin\Desktop\golf bag
2018-02-05 20:07 - 2018-02-07 12:51 - 000000000 ___DC C:\Users\admin\Desktop\2018-02-05 Golf bag
2018-02-05 19:58 - 2018-02-09 16:38 - 000000000 ___DC C:\Windows\Minidump
2018-02-04 12:43 - 2018-02-04 12:43 - 000550424 ____C () C:\Users\admin\Downloads\iExplorerSetup.exe
2018-02-03 15:28 - 2018-02-03 15:28 - 000001791 ____C C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-01-30 09:26 - 2018-01-30 09:26 - 000431151 ____C C:\Users\admin\Downloads\agl_bill (2).pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-28 16:56 - 2015-10-15 13:23 - 000020110 ____C C:\Users\admin\Downloads\FRST.txt
2018-02-28 16:56 - 2015-10-13 15:59 - 000000000 ___DC C:\FRST
2018-02-28 15:08 - 2009-07-14 14:20 - 000000000 ___DC C:\Windows\tracing
2018-02-28 11:34 - 2015-05-13 19:34 - 000004476 ____C C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-28 11:29 - 2009-07-14 15:45 - 000026000 ____C C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-02-28 11:29 - 2009-07-14 15:45 - 000026000 ____C C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-02-28 11:25 - 2009-07-14 16:13 - 000783606 ____C C:\Windows\system32\PerfStringBackup.INI
2018-02-28 11:25 - 2009-07-14 14:20 - 000000000 ___DC C:\Windows\inf
2018-02-28 11:21 - 2015-06-13 15:04 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2018-02-28 11:21 - 2009-07-14 16:08 - 000000006 ___HC C:\Windows\Tasks\SA.DAT
2018-02-27 16:37 - 2016-06-16 19:36 - 000002224 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-27 16:37 - 2016-06-16 19:36 - 000002183 ____C C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-27 16:23 - 2009-07-14 14:20 - 000000000 ___DC C:\Windows\system32\NDF
2018-02-27 16:15 - 2017-11-10 11:41 - 000004128 ____C C:\Windows\System32\Tasks\CCleaner Update
2018-02-27 11:12 - 2014-07-24 17:30 - 000000000 ___DC C:\Windows\system32\Macromed
2018-02-26 17:59 - 2016-04-17 23:08 - 000000000 ___DC C:\ProgramData\WinZip
2018-02-26 17:58 - 2016-04-17 23:08 - 000000000 ___DC C:\Users\admin\AppData\Local\WinZip
2018-02-26 17:58 - 2016-04-17 23:08 - 000000000 ___DC C:\Program Files\WinZip
2018-02-26 17:57 - 2015-10-08 17:07 - 000004312 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-02-26 17:57 - 2014-07-24 17:30 - 000803328 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-02-26 17:57 - 2014-07-24 17:30 - 000144896 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-26 17:57 - 2014-07-24 17:30 - 000000000 ___DC C:\Windows\SysWOW64\Macromed
2018-02-25 21:54 - 2016-05-13 21:12 - 000002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-02-24 21:23 - 2017-04-09 13:53 - 000000000 ___DC C:\ProgramData\AVAST Software
2018-02-24 21:23 - 2017-02-14 22:04 - 000000782 ____C C:\Users\Public\Desktop\CCleaner.lnk
2018-02-16 22:37 - 2016-02-06 17:00 - 000000000 ___DC C:\AdwCleaner
2018-02-16 22:22 - 2015-09-13 21:18 - 000035142 ____C C:\Users\admin\Downloads\MTB.txt
2018-02-15 15:38 - 2014-12-12 08:38 - 000000000 ___DC C:\Windows\system32\appraiser
2018-02-15 15:38 - 2009-07-14 15:45 - 000294496 ____C C:\Windows\system32\FNTCACHE.DAT
2018-02-14 21:42 - 2014-04-29 13:08 - 000000000 ___DC C:\Windows\system32\MRT
2018-02-14 21:41 - 2017-10-11 21:37 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-14 21:41 - 2014-09-18 13:59 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-02-14 12:02 - 2015-05-13 19:14 - 000000000 ___DC C:\Qoobox
2018-02-14 11:43 - 2016-01-30 14:48 - 000003554 ____C C:\Windows\System32\Tasks\GarminUpdaterTask
2018-02-14 11:43 - 2014-10-10 16:17 - 000000000 ___DC C:\Program Files (x86)\Garmin
2018-02-14 11:43 - 2014-09-22 11:05 - 000000000 ___DC C:\ProgramData\Package Cache
2018-02-12 18:02 - 2017-11-10 11:29 - 000000000 ___DC C:\Users\admin\Desktop\OpenOffice 4.1.4 (en-US) Installation Files
2018-02-12 17:59 - 2015-05-13 19:10 - 000000000 ___DC C:\Users\admin\AppData\Local\CrashDumps
2018-02-09 23:05 - 2015-11-01 19:47 - 000000000 ___DC C:\Users\admin\AppData\Local\Deployment
2018-02-04 21:31 - 2014-09-17 14:14 - 000759576 ____C C:\Windows\SysWOW64\PerfStringBackup.INI
2018-02-04 12:43 - 2015-11-01 19:47 - 000000000 ___DC C:\Users\admin\AppData\Local\Apps\2.0
2018-02-03 15:38 - 2017-12-03 16:24 - 000000000 ___DC C:\Users\admin\Desktop\2017-12-03 exersize machines
2018-02-03 15:26 - 2016-02-07 13:16 - 000000000 ___DC C:\Users\admin\Desktop\Items I Don't Use
2018-01-30 18:03 - 2014-07-26 09:32 - 000001583 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2018-01-30 11:29 - 2014-07-26 04:19 - 000000000 ___DC C:\Users\admin\AppData\Local\ElevatedDiagnostics
 
==================== Files in the root of some directories =======
 
2014-12-24 10:46 - 2015-07-04 22:55 - 000000115 ____C () C:\Users\admin\AppData\Roaming\LogFile.txt
2014-07-24 20:02 - 2014-08-02 20:10 - 000018526 ____C () C:\Users\admin\AppData\Roaming\UserTile.png
2014-09-26 21:22 - 2016-02-01 18:43 - 000004608 ____C () C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2016-11-29 19:47
 
==================== End of FRST.txt ============================
==========================================================
 
 
==================== Accounts: =============================
 
admin (S-1-5-21-1382244373-2055223747-3369237834-1003 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-1382244373-2055223747-3369237834-500 - Administrator - Disabled)
Guest (S-1-5-21-1382244373-2055223747-3369237834-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1382244373-2055223747-3369237834-1005 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 28.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.161 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.161 - Adobe Systems Incorporated)
ANT Drivers Installer x64 (HKLM\...\{00EC0123-5EC2-4D75-830C-EF11667E74E8}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{D4C80B0C-CF67-43A7-90C3-466853543B54}) (Version: 6.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B2A2E8AF-BC48-4191-B2C4-3846A19835CA}) (Version: 6.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{AA7D90D2-2387-4FA5-A3AF-96811BE49BFD}) (Version: 11.0.5.14 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{19589375-5C58-4AFA-842F-8B34744CCEAD}) (Version: 2.5.0.1 - Apple Inc.)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.1.2326 - AVAST Software)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Brother MFL-Pro Suite MFC-J430W (HKLM-x32\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.10.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Elevated Installer (HKLM-x32\...\{9AB7E852-655C-4BDE-9042-1D3E6807C85A}) (Version: 6.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
eM Client (HKLM-x32\...\{2A4CAF55-4B18-4B61-BE9E-94A54209F547}) (Version: 7.0.27943.0 - eM Client Inc.)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology) Hidden
Garmin Express (HKLM-x32\...\{E695D74A-9567-46DA-A4EE-0E191F21194B}) (Version: 6.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{fb1ff7db-c0d2-43c4-99bf-5b2fa4f9ca0b}) (Version: 6.1.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\...\{7C8FDEF1-F311-459C-B3CC-EEF73C721BFD}) (Version: 6.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.186 - Google Inc.)
Google Photos Backup (HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\Google Photos Backup) (Version: 1.1.0.239 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
iCloud (HKLM\...\{694E3E02-E14A-4BB2-A970-CF7F017FD5CC}) (Version: 7.3.0.20 - Apple Inc.)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4264 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
iTunes (HKLM\...\{1D7D1271-5258-4F5A-B8C1-7176BF398782}) (Version: 12.7.3.46 - Apple Inc.)
Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
K-Lite Codec Pack 9.9.9 (64-bit) (HKLM\...\KLiteCodecPack64_is1) (Version: 9.9.9 - )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft .NET Framework 4.6.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01590 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nero 2015 (HKLM-x32\...\{E6626251-ED62-469C-821F-D75C50154C48}) (Version: 16.0.02800 - Nero AG)
Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG)
ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
OpenOffice 4.1.2 (HKLM-x32\...\{E6AD67BB-1C33-4AB3-A387-E0D48137AB70}) (Version: 4.12.9782 - Apache Software Foundation)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
Picasa Uploader (HKLM-x32\...\{60945EFA-28EB-8202-19C1-70DD667075CB}) (Version: 1.2 - UNKNOWN) Hidden
Picasa Uploader (HKLM-x32\...\com.webkinesis.PicasaUploaderDesktop) (Version: 1.2 - UNKNOWN)
Platform (HKLM-x32\...\{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Hidden
Prerequisite installer (HKLM-x32\...\{799AFA36-4EA5-4323-8689-74C06645A26B}) (Version: 16.0.0000 - Nero AG) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.65.1025.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8036 - Realtek Semiconductor Corp.)
Revo Uninstaller 2.0.3 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.3 - VS Revo Group, Ltd.)
Speccy (HKLM\...\Speccy) (Version: 1.31 - Piriform)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1220 - SUPERAntiSpyware.com)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinZip 20.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. )
WinZip 22.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24119}) (Version: 22.0.12706 - Corel Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382244373-2055223747-3369237834-1003_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-02-24] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-02-24] (AVAST Software)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2018-01-10] (Apple Inc.)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-02-24] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-08-09] (Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2015-08-09] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-02-24] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0405B51B-4831-47D7-8E5B-9C08E196383F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-10-12] (Apple Inc.)
Task: {06AD8BBC-4EE2-4CCC-B9FC-96F7920DD15A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-28] (Google Inc.)
Task: {0F6EC959-F178-4BE4-8648-50FD2E96D7A2} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {1959C1CE-1BFB-4585-9E3C-261776F304DB} - System32\Tasks\WinSysCleanUAC => C:\Program Files\WinSysClean X7 Free\WinSysClean.exe
Task: {210987CC-4489-49A4-BB8D-A5BBD0F3D60E} - System32\Tasks\{C1A9C442-4B24-4CDD-A3E2-224629962D50} => C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe [2016-02-11] (Malwarebytes)
Task: {3BFC7575-F499-437F-9395-B80B8F6010AF} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG)
Task: {4AFDE148-4A79-41B9-BEBB-E3E709BD1C63} - System32\Tasks\Java™ Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
Task: {58953F2D-6933-4831-B64C-5CE6BF580CFC} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2018-02-08] ()
Task: {58B2BFCF-0C50-4C60-AAB8-A17E6124A31E} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-12-11] (WinZip)
Task: {5AD36195-400D-4199-850B-9755CCD48C22} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-02-26] (Adobe Systems Incorporated)
Task: {5D54E269-98C1-42DF-B116-2F15782CA2F5} - System32\Tasks\TechUtilities => C:\Program Files (x86)\TechUtilities\TechUtilities.exe
Task: {629E1CFE-AEB8-4ED0-92E6-17841F82A111} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1382244373-2055223747-3369237834-1003Core => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2015-07-28] (Google Inc.)
Task: {63D9F03C-C81C-4DBD-81C2-8A7A3BD52BAD} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-02-24] (AVAST Software)
Task: {67755926-8CCC-4F06-B6C8-DFA49B61191D} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation)
Task: {6912F541-0041-4065-96E7-1DC93E419352} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {70F0BDAD-0F49-4A32-A4A7-5F5948B7AD63} - System32\Tasks\{174DEEA9-3151-4838-BF86-D9BEEBD7D815} => C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe [2016-02-11] (Malwarebytes)
Task: {7E8F74B9-47EC-4432-AB3D-E8573359067B} - System32\Tasks\{08A9D6C9-FD5C-4651-B5D7-5AD72F1817EA} => C:\Windows\system32\pcalua.exe -a "F:\Eraser 6.0.10.2620.exe" -d F:\
Task: {8A8A8C04-621A-4B50-94B5-19515777E42F} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {94D5D80C-E680-4549-A0DA-ABD9AE53F51A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-28] (Google Inc.)
Task: {B49311F2-B63D-43BF-B6B1-5F85F2B142BB} - System32\Tasks\{7547D37E-CD86-486F-A4CA-FEAB2DACD1BE} => C:\Program Files (x86)\eM Client\MailClient.exe [2016-10-21] (eM Client s.r.o.)
Task: {B86372F2-471A-4FD6-A3B6-F7675B38617C} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-02-25] (AVAST Software)
Task: {BC6D9983-2200-4941-A254-4204C96F99D7} - System32\Tasks\{8F89AEC2-DBE7-4111-8A04-5E1C0A871CA6} => C:\Windows\system32\pcalua.exe -a C:\ProgramData\LGMOBILEAX\LGMLauncher.exe -d C:\ProgramData\LGMOBILEAX
Task: {C1A620F7-8D14-4AC5-BCFF-F8829ED14DB8} - System32\Tasks\{4E642B1D-5C2A-4AFF-9A0B-A67BB64CBA9D} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {CEE35246-18C0-4A04-838D-6109CF458E17} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-08] (Piriform Ltd)
Task: {D9390939-DDBB-4AEA-8352-608FDC39FA74} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1382244373-2055223747-3369237834-1003UA => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2015-07-28] (Google Inc.)
Task: {EDDC887F-40EC-46B4-A323-EE2950651455} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-08] (Piriform Ltd)
Task: {F395D902-20A9-4FD3-93B3-B423569F8134} - System32\Tasks\{8FCBD6AA-B3D5-4E22-A673-93D0CC8746B4} => "c:\program files\internet explorer\iexplore.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.18.0.105&LastError=404
Task: {F72FA3F2-C294-429A-9F0E-5D44F67C2404} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {F97D4AFE-C859-475F-A7C0-36A5116B44CE} - System32\Tasks\{0A009F85-A859-48F7-AC59-3E487161BD6D} => C:\Windows\system32\pcalua.exe -a "C:\Users\admin\Downloads\B2CAppSetup (1).exe" -d C:\Users\admin\Desktop
Task: {FD240B49-381E-4CE3-B763-24E195318611} - System32\Tasks\{F55D658D-A66D-48EE-83B8-F4321FD3DD61} => C:\Windows\system32\pcalua.exe -a "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KIYR1A8O\Adobe_Air_v15.0.0.356.exe" -d C:\Users\admin\Desktop
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1382244373-2055223747-3369237834-1003Core.job => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1382244373-2055223747-3369237834-1003UA.job => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\TechUtilities.job => C:\Program Files (x86)\TechUtilities\TechUtilities.exe-t C:\Program Files (x86)\TechUtilities\TechUtilities.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2018-01-05 00:13 - 2018-01-05 00:13 - 001356088 ____C () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-01-05 00:14 - 2018-01-05 00:14 - 000088888 ____C () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2018-01-22 03:15 - 2018-01-22 03:15 - 001356088 ____C () C:\Program Files\iTunes\libxml2.dll
2018-01-22 03:15 - 2018-01-22 03:15 - 000088888 ____C () C:\Program Files\iTunes\zlib1.dll
2017-09-01 22:15 - 2017-09-01 22:15 - 000495872 ____C () C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe
2017-10-08 12:07 - 2017-12-12 13:47 - 002301384 ____C () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-02-27 16:37 - 2018-02-22 14:57 - 004433752 ____C () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libglesv2.dll
2018-02-27 16:37 - 2018-02-22 14:57 - 000099672 ____C () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libegl.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000287960 ____C () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000280280 ____C () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2018-02-27 10:48 - 2018-02-27 10:48 - 005826192 ____C () C:\Program Files\AVAST Software\Avast\defs\18022604\algo.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000756952 ____C () C:\Program Files\AVAST Software\Avast\ffl2.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000172248 ____C () C:\Program Files\AVAST Software\Avast\hns_tools.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000963288 ____C () C:\Program Files\AVAST Software\Avast\shepherdsync.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000468696 ____C () C:\Program Files\AVAST Software\Avast\gui_cache.dll
2018-02-28 11:21 - 2018-02-28 11:21 - 005826192 ____C () C:\Program Files\AVAST Software\Avast\defs\18022716\algo.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000339160 ____C () C:\Program Files\AVAST Software\Avast\streamback_avast.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 067109376 ____C () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-02-24 21:26 - 2018-02-24 21:26 - 000275672 ____C () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2018-01-05 00:14 - 2018-01-05 00:14 - 001042232 ____C () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2018-01-05 00:14 - 2018-01-05 00:14 - 000076088 ____C () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2018-01-05 00:14 - 2018-01-05 00:14 - 000189752 ____C () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 13:34 - 2017-02-17 13:13 - 000000867 ____C C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1382244373-2055223747-3369237834-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AeLookupSvc => 3
MSCONFIG\Services: ALG => 3
MSCONFIG\Services: AppIDSvc => 3
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: aspnet_state => 3
MSCONFIG\Services: AudioEndpointBuilder => 2
MSCONFIG\Services: AudioSrv => 2
MSCONFIG\Services: avgsvc => 2
MSCONFIG\Services: AxInstSV => 3
MSCONFIG\Services: BDESVC => 3
MSCONFIG\Services: BFE => 2
MSCONFIG\Services: BITS => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: Browser => 3
MSCONFIG\Services: BrYNSvc => 3
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: CertPropSvc => 3
MSCONFIG\Services: clr_optimization_v2.0.50727_32 => 3
MSCONFIG\Services: clr_optimization_v2.0.50727_64 => 3
MSCONFIG\Services: clr_optimization_v4.0.30319_32 => 2
MSCONFIG\Services: clr_optimization_v4.0.30319_64 => 2
MSCONFIG\Services: COMSysApp => 3
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: CryptSvc => 2
MSCONFIG\Services: defragsvc => 3
MSCONFIG\Services: Dhcp => 2
MSCONFIG\Services: DiagTrack => 2
MSCONFIG\Services: Dnscache => 2
MSCONFIG\Services: dot3svc => 3
MSCONFIG\Services: DPS => 2
MSCONFIG\Services: EapHost => 3
MSCONFIG\Services: EFS => 3
MSCONFIG\Services: ehRecvr => 2
MSCONFIG\Services: ehSched => 2
MSCONFIG\Services: eventlog => 2
MSCONFIG\Services: EventSystem => 2
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: fdPHost => 3
MSCONFIG\Services: FDResPub => 2
MSCONFIG\Services: FontCache => 2
MSCONFIG\Services: FontCache3.0.0.0 => 3
MSCONFIG\Services: fsssvc => 3
MSCONFIG\Services: Garmin Device Interaction Service => 3
MSCONFIG\Services: gpsvc => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: gusvc => 3
MSCONFIG\Services: hidserv => 3
MSCONFIG\Services: hkmsvc => 3
MSCONFIG\Services: hmpalertsvc => 2
MSCONFIG\Services: HomeGroupListener => 2
MSCONFIG\Services: HomeGroupProvider => 2
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: idsvc => 3
MSCONFIG\Services: IEEtwCollectorService => 3
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: IKEEXT => 2
MSCONFIG\Services: Intel® Capability Licensing Service Interface => 2
MSCONFIG\Services: Intel® Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: IPBusEnum => 3
MSCONFIG\Services: iphlpsvc => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: KeyIso => 3
MSCONFIG\Services: KtmRm => 3
MSCONFIG\Services: LanmanServer => 2
MSCONFIG\Services: LanmanWorkstation => 2
MSCONFIG\Services: LBTServ => 3
MSCONFIG\Services: lltdsvc => 3
MSCONFIG\Services: lmhosts => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MB3Service => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: MMCSS => 2
MSCONFIG\Services: MpsSvc => 2
MSCONFIG\Services: MSCamSvc => 2
MSCONFIG\Services: MSDTC => 3
MSCONFIG\Services: MSiSCSI => 3
MSCONFIG\Services: msiserver => 3
MSCONFIG\Services: napagent => 3
MSCONFIG\Services: NAUpdate => 2
MSCONFIG\Services: Netlogon => 3
MSCONFIG\Services: Netman => 3
MSCONFIG\Services: netprofm => 3
MSCONFIG\Services: NlaSvc => 2
MSCONFIG\Services: nsi => 2
MSCONFIG\Services: p2pimsvc => 3
MSCONFIG\Services: p2psvc => 3
MSCONFIG\Services: PcaSvc => 2
MSCONFIG\Services: PerfHost => 3
MSCONFIG\Services: pla => 3
MSCONFIG\Services: PNRPAutoReg => 3
MSCONFIG\Services: PNRPsvc => 3
MSCONFIG\Services: PolicyAgent => 3
MSCONFIG\Services: Power => 2
MSCONFIG\Services: ProtectedStorage => 3
MSCONFIG\Services: QWAVE => 3
MSCONFIG\Services: RasAuto => 3
MSCONFIG\Services: RasMan => 3
MSCONFIG\Services: RemoteRegistry => 3
MSCONFIG\Services: RpcEptMapper => 2
MSCONFIG\Services: RpcLocator => 3
MSCONFIG\Services: SamSs => 2
MSCONFIG\Services: SCardSvr => 3
MSCONFIG\Services: SCPolicySvc => 3
MSCONFIG\Services: SDRSVC => 3
MSCONFIG\Services: seclogon => 3
MSCONFIG\Services: Secunia PSI Agent => 2
MSCONFIG\Services: SENS => 2
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: ShellHWDetection => 2
MSCONFIG\Services: SNMPTRAP => 3
MSCONFIG\Services: Spooler => 2
MSCONFIG\Services: sppuinotify => 3
MSCONFIG\Services: SSDPSRV => 3
MSCONFIG\Services: SstpSvc => 3
MSCONFIG\Services: stisvc => 2
MSCONFIG\Services: swprv => 3
MSCONFIG\Services: SysMain => 2
MSCONFIG\Services: TabletInputService => 3
MSCONFIG\Services: TapiSrv => 3
MSCONFIG\Services: TermService => 2
MSCONFIG\Services: Themes => 2
MSCONFIG\Services: THREADORDER => 3
MSCONFIG\Services: TrkWks => 2
MSCONFIG\Services: TrustedInstaller => 3
MSCONFIG\Services: UI0Detect => 3
MSCONFIG\Services: upnphost => 3
MSCONFIG\Services: UxSms => 2
MSCONFIG\Services: VaultSvc => 3
MSCONFIG\Services: vds => 3
MSCONFIG\Services: VSS => 3
MSCONFIG\Services: W32Time => 2
MSCONFIG\Services: WatAdminSvc => 3
MSCONFIG\Services: wbengine => 3
MSCONFIG\Services: WbioSrvc => 3
MSCONFIG\Services: wcncsvc => 3
MSCONFIG\Services: WcsPlugInService => 3
MSCONFIG\Services: WdiServiceHost => 3
MSCONFIG\Services: WdiSystemHost => 3
MSCONFIG\Services: WebClient => 3
MSCONFIG\Services: Wecsvc => 3
MSCONFIG\Services: wercplsupport => 3
MSCONFIG\Services: WerSvc => 3
MSCONFIG\Services: WinDefend => 2
MSCONFIG\Services: WinHttpAutoProxySvc => 3
MSCONFIG\Services: Winmgmt => 2
MSCONFIG\Services: WinRM => 3
MSCONFIG\Services: Wlansvc => 2
MSCONFIG\Services: wlidsvc => 2
MSCONFIG\Services: wmiApSrv => 3
MSCONFIG\Services: WMPNetworkSvc => 2
MSCONFIG\Services: WPCSvc => 3
MSCONFIG\Services: WPDBusEnum => 3
MSCONFIG\Services: WSCSVC => 2
MSCONFIG\Services: WSearch => 2
MSCONFIG\Services: wuauserv => 2
MSCONFIG\Services: wudfsvc => 3
MSCONFIG\Services: WwanSvc => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FAH.lnk => C:\Windows\pss\FAH.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk => C:\Windows\pss\Secunia PSI Tray.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Update Notifier.lnk => C:\Windows\pss\Update Notifier.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Preloader.lnk => C:\Windows\pss\WinZip Preloader.lnk.CommonStartup
MSCONFIG\startupreg: AvgUi => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: HDAudDeck => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{57A02B0D-BD01-429B-B831-D0DD80761C7D}C:\program files (x86)\nero\km\nmdllhost.exe] => (Block) C:\program files (x86)\nero\km\nmdllhost.exe
FirewallRules: [UDP Query User{E6E8020F-281C-4352-B9EF-961B435B910E}C:\program files (x86)\nero\km\nmdllhost.exe] => (Block) C:\program files (x86)\nero\km\nmdllhost.exe
FirewallRules: [{F7B9B184-A5E3-4D81-B4CC-D437F99209F5}] => (Allow) LPort=80
FirewallRules: [{A7E33524-D520-408C-97C5-381209804A1F}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{D3FDC048-F2C3-447E-8276-609D5275B361}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{BBA9ED2F-CCD2-4BF1-8109-863FE3653C7B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
18-02-2018 14:37:18 Windows Update
21-02-2018 15:08:44 Windows Update
24-02-2018 20:19:58 Windows Update
28-02-2018 11:31:57 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/27/2018 04:31:37 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Users\admin\Downloads\esetsmartinstaller_enu (1).exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
 
Error: (02/27/2018 04:31:36 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Users\admin\Downloads\esetsmartinstaller_enu.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
 
Error: (02/25/2018 11:03:12 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
Error: (02/25/2018 11:03:12 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
 
Context: Windows Application
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
Error: (02/25/2018 11:03:12 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.
 
Context: Windows Application, SystemIndex Catalog
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
Error: (02/25/2018 11:03:12 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.
 
Context: Windows Application, SystemIndex Catalog
 
Details:
Element not found.  (HRESULT : 0x80070490) (0x80070490)
 
Error: (02/25/2018 11:03:12 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.JetPropStore> cannot be initialized.
 
Context: Windows Application, SystemIndex Catalog
 
Details:
The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
 
Error: (02/25/2018 11:03:12 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: The Windows Search Service cannot load the property store information.
 
Context: Windows Application, SystemIndex Catalog
 
Details:
The content index database is corrupt.  (HRESULT : 0xc0041800) (0xc0041800)
 
 
System errors:
=============
Error: (02/28/2018 11:21:25 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 105.
 
Error: (02/28/2018 11:21:14 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
avipbb
avkmgr
 
Error: (02/27/2018 04:19:39 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 105.
 
Error: (02/27/2018 04:19:31 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
avipbb
avkmgr
 
Error: (02/27/2018 04:07:25 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 105.
 
Error: (02/27/2018 04:05:38 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
avipbb
avkmgr
 
Error: (02/27/2018 04:05:39 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
 
Error: (02/27/2018 11:10:24 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 105.
 
 
Windows Defender:
===================================
Date: 2017-02-28 22:23:07.349
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified. 
Signature version:0.0.0.0
Engine version:0.0.0.0
 
CodeIntegrity:
===================================
 
Date: 2015-12-30 12:21:40.459
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-12-30 12:21:40.449
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-05-13 18:20:51.437
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-05-13 18:20:51.422
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-05-13 18:19:44.108
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\admin\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-05-13 18:19:44.092
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\admin\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-05-13 18:19:44.077
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\admin\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2015-05-13 18:19:44.045
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\admin\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
Processor: Intel® Pentium® CPU G3240 @ 3.10GHz
Percentage of memory in use: 23%
Total physical RAM: 8061.34 MB
Available physical RAM: 6144.18 MB
Total Virtual: 16120.84 MB
Available Virtual: 13589.75 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:111.25 GB) (Free:20.2 GB) NTFS
Drive d: () (Fixed) (Total:465.75 GB) (Free:460.48 GB) NTFS
 
\\?\Volume{9285e243-fd8d-11e2-8865-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: 8507E427)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: E90BE90B)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

Edited by Platypus, 28 February 2018 - 01:20 AM.
Deleted duplicates

Eddee

BC AdBot (Login to Remove)

 


#2 ed-e-dee

ed-e-dee
  • Topic Starter

  • Members
  • 276 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Australia
  • Local time:04:31 AM

Posted 28 February 2018 - 01:34 AM

Attached File  Fixlog.txt   2.83KB   4 downloadsAttached File  FRST.txt   62.85KB   2 downloads


Eddee

#3 nasdaq

nasdaq

  • Malware Response Team
  • 40,500 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:31 PM

Posted 28 February 2018 - 08:32 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:


CHR Extension: (Discrete Search) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjhiajafgpbijomjilfpkfemmhdoponb [2016-12-13]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
U3 aswbdisk; no ImagePath
S3 b06bdrv; \SystemRoot\system32\drivers\bxvbda.sys [X]
S3 farflt; \??\C:\Windows\system32\drivers\farflt.sys [X]

ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {F395D902-20A9-4FD3-93B3-B423569F8134} - System32\Tasks\{8FCBD6AA-B3D5-4E22-A673-93D0CC8746B4} => "c:\program files\internet explorer\iexplore.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.18.0.105&LastError=404

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please let me know what problem persists.

#4 nasdaq

nasdaq

  • Malware Response Team
  • 40,500 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:31 PM

Posted 06 March 2018 - 09:17 AM

Are you still with me?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users